Hackers change the DNS settings of Wi-Fi units in inns and convention facilities to redirect customers to a pretend Microsoft 365 login web page.
The marketing campaign has been ongoing since not less than June and impacts organizations throughout quite a lot of sectors, together with monetary providers, skilled providers, authorized, healthcare, power, and retail.
Cybersecurity agency ReliaQuest has recognized compromised Wi-Fi gateways in a number of U.S. cities and different elements of the world, together with India and Saudi Arabia.
As a result of these units are used for company occasions, hijacking your Microsoft 365 account may give an attacker entry to delicate enterprise info, communications, and personal paperwork.
“We noticed site visitors to those compromised gateways from organizations in quite a lot of industries, together with monetary providers, skilled providers, authorized, healthcare, power, and retail. This confirms that that is probably a marketing campaign concentrating on workers who journey wherever they join, slightly than sector-specific targets,” ReliaQuest mentioned.
Researchers consider this exercise is much like the FrostArmada router-based marketing campaign attributed to the Russian spy group APT28 (also referred to as Fancy Bear and Forest Blizzard).
assault chain
It’s unclear how the preliminary entry to the Wi-Fi equipment was gained, however ReliaQuest says the attackers could have exploited poorly protected, uncovered administration interfaces (corresponding to SSH, SNMP, or net administration dashboards) or vulnerabilities.
As soon as an attacker positive factors administrative entry, they’ll modify the gateway’s DNS settings to redirect connections to authentic domains to infrastructure underneath their management.
Based on ReliaQuest, the attackers registered not less than 4 domains to arrange a pretend Microsoft login portal: m365-owa(.)com, owa-ms365(.)com, ms365-device(.)com, and ms365-live(.)com.
As soon as the DNS settings have been modified, when customers attempt to entry the authentic Microsoft login portal, they are going to be directed to a hacker’s phishing web page to enter their credentials.
In some circumstances, we noticed a tool code authentication circulate the place the goal was redirected to a pretend Microsoft web page with a immediate.
“What the person does not see is that by approving the immediate, they’re approving the session initiated by the attacker,” ReliaQuest mentioned. The researchers be aware that when a request initiated by an attacker is authorized, a authentic OAuth token is issued to the attacker’s shopper.
This bypasses multi-factor authentication (MFA) safety with out stealing credentials or intercepting entry tokens.

Supply: LiliaQuest
In roughly one-third of the incidents investigated, attackers tried to take advantage of Net Proxy Auto-Discovery (WPAD) by responding to Home windows’ computerized WPAD lookups with malicious Proxy Auto-Configuration (PAC) recordsdata.
This is able to theoretically route site visitors from Home windows apps, together with Chrome, by an attacker-controlled proxy, however ReliaQuest couldn’t verify whether or not these assaults have been profitable.
The researchers additionally emphasised that utilizing a public DNS server, corresponding to Google’s 8.8.8.8, won’t stop this assault, because the gateway forges the cleartext request earlier than it reaches the supposed resolver.
ReliaQuest recommends utilizing always-on, full-tunnel VPN and strict mode encrypted DNS to make sure safety towards these assaults.
As well as, the cybersecurity agency recommends disabling WPAD, checking logs for suspicious exercise, and disabling the Microsoft Entra ID system code authentication circulate if not wanted.
Safety groups doc 54% of profitable assaults and subject a warning on solely 14%. The remaining strikes invisibly by the setting.
Picus’ whitepaper exhibits the right way to check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
